Please ensure Javascript is enabled for purposes of website accessibility
Apple Busts Facebook for Distributing Data-Sucking App
gvw_ap_news
By Associated Press
Published 6 years ago on
January 31, 2019

Share

NEW YORK — Apple says Facebook can no longer distribute an app that paid users, including teenagers, to extensively track their phone and web use.

“I don’t think they make it very clear to users precisely what level of access they were granting when they gave permission. There is simply no way the users understood this.” — Will Strafach, mobile app security researcher
In doing so, Apple closed off Facebook’s efforts to sidestep Apple’s app store and its tighter rules on privacy.
The tech blog TechCrunch reported late Tuesday that Facebook paid people about $20 a month to install and use the Facebook Research app. While Facebook says this was done with permission, the company has a history of defining “permission” loosely and obscuring what data it collects.
“I don’t think they make it very clear to users precisely what level of access they were granting when they gave permission,” mobile app security researcher Will Strafach said Wednesday. “There is simply no way the users understood this.”
He said Facebook’s claim that users understood the scope of data collection was “muddying the waters.”
Facebook says fewer than 5 percent of the app’s users were teens and they had parental permission. Nonetheless, the revelation is yet another blemish on Facebook’s track record on privacy and could invite further regulatory scrutiny.

App Appears to Be Available for Android Phones

And it comes less than a week after court documents revealed that Facebook allowed children to rack up huge bills on digital games and that it had rejected recommendations for addressing it for fear of hurting revenue growth.
For now, the app appears to be available for Android phones, though not through Google’s main app store. Google had no comment Wednesday.
Apple said Facebook was distributing Facebook Research through an internal-distribution mechanism meant for company employees, not outsiders. Apple has revoked that capability.
TechCrunch reported separately Wednesday that Google was using the same privileged access to Apple’s mobile operating system for a market-research app, Screenwise Meter. Asked about it by The Associated Press, Google said it had disabled the app on Apple devices and apologized for its “mistake.”
The company said Google had always been “upfront with users” about how it used data collected by the app, which offered users points that could be accrued for gift cards. In contrast to the Facebook Research app, Google said its Screenwise Meter app never asked users to let the company circumvent network encryption, meaning it is far less intrusive.
Facebook is still permitted to distribute apps through Apple’s app store, though such apps are reviewed by Apple ahead of time. And Apple’s move Wednesday restricts Facebook’s ability to test those apps — including core apps such as Facebook and Instagram — before they are released through the app store.
Facebook previously pulled an app called Onavo Protect from Apple’s app store because of its stricter requirements. But Strafach, who dismantled the Facebook Research app on TechCrunch’s behalf, told the AP that it was mostly Onavo repackaged and rebranded, as the two apps shared about 98 percent of their code.

Traffic-Capturing Tools Are Only Supposed to Be for Trusted Partners

As of Wednesday, a disclosure form on Betabound, one of the services that distributed Facebook Research, informed prospective users that by installing Facebook Research, they are letting Facebook collect a range of data. This includes information on apps users have installed, when they use them and what they do on them. Information is also collected on how other people interact with users and their content within those apps, according to the disclosure.

“This is very flagrantly not allowed. It’s mind-blowing how defiant Facebook was acting.” Will Strafach, mobile app security researcher
Betabound warned that Facebook may collect information even when an app or web browser uses encryption.
Strafach said emails, social media activities, private messages and just about anything else could be intercepted. He said the only data absolutely safe from snooping are from services, such as Signal and Apple’s iMessages, that fully encrypt messages prior to transmission, a method known as end-to-end encryption.
Strafach, who is CEO of Guardian Mobile Firewall, said he was aghast to discover Facebook caught red-handed violating Apple’s trust.
He said such traffic-capturing tools are only supposed to be for trusted partners to use internally. Instead, he said Facebook was scooping up all incoming and outgoing data traffic from unwitting members of the public — in an app geared toward teenagers.
“This is very flagrantly not allowed,” Strafach said. “It’s mind-blowing how defiant Facebook was acting.”

DON'T MISS

North Korean Leader Says Past Diplomacy Only Confirmed US Hostility

DON'T MISS

Democrats Strike Deal to Get More Biden Judges Confirmed Before Congress Adjourns

DON'T MISS

Newsom Gaslights on Potential Gas Price Hikes in Fresno Visit

DON'T MISS

Automakers to Trump: Please Require Us to Sell Electric Vehicles

DON'T MISS

President Biden Welcomes 2024 NBA Champion Boston Celtics to White House

DON'T MISS

Ohtani Makes History With 3rd MVP, Judge Claims 2nd AL Honor

DON'T MISS

Trump Chooses Pam Bondi for Attorney General Pick After Gaetz Withdraws

DON'T MISS

Average Rate on a 30-Year Mortgage in the US Rises to Highest Level Since July

DON'T MISS

Cutting in Line? American Airlines’ New Boarding Tech Might Stop You at Now Over 100 Airports

DON'T MISS

MLB Will Test Robot Umpires at 13 Spring Training Ballparks Hosting 19 Teams

UP NEXT

Bomb Cyclone Kills 1 and Knocks Out Power to Over Half a Million Homes Across the Northwest US

UP NEXT

Volunteers Came Back to Nonprofits in 2023, After the Pandemic Tanked Participation

UP NEXT

New Study: Proposed Trump Tariffs Could Cost US Consumers $78 Billion a Year

UP NEXT

Riders Stuck in Midair for Over 2 Hours on Knott’s Berry Farm Ride

UP NEXT

Shouting Racial Slurs, Neo-Nazi Marchers Shock Ohio’s Capital

UP NEXT

More Logging Is Proposed to Help Curb Wildfires in the US Pacific Northwest

UP NEXT

Scientists Fear What’s Next for Public Health if RFK Jr. Is Allowed To ‘Go Wild’

UP NEXT

Warren Slams Biden Admin for Failing to Hold Israel Accountable on Gaza Aid

UP NEXT

Suicides in the US Military Increased in 2023, Continuing a Long-Term Trend

UP NEXT

New FDA Rules for TV Drug Ads: Simpler Language and No Distractions

Automakers to Trump: Please Require Us to Sell Electric Vehicles

2 hours ago

President Biden Welcomes 2024 NBA Champion Boston Celtics to White House

2 hours ago

Ohtani Makes History With 3rd MVP, Judge Claims 2nd AL Honor

2 hours ago

Trump Chooses Pam Bondi for Attorney General Pick After Gaetz Withdraws

2 hours ago

Average Rate on a 30-Year Mortgage in the US Rises to Highest Level Since July

3 hours ago

Cutting in Line? American Airlines’ New Boarding Tech Might Stop You at Now Over 100 Airports

3 hours ago

MLB Will Test Robot Umpires at 13 Spring Training Ballparks Hosting 19 Teams

3 hours ago

Death Toll in Gaza From Israel-Hamas War Passes 44,000, Palestinian Officials Say

4 hours ago

Jussie Smollett’s Conviction in 2019 Attack on Himself Is Overturned

4 hours ago

Fresno Council Lowers Speed Limits on Friant and Audubon

4 hours ago

North Korean Leader Says Past Diplomacy Only Confirmed US Hostility

SEOUL, South Korea — North Korean leader Kim Jong Un said his past negotiations with the United States only confirmed Washington’s ...

24 minutes ago

24 minutes ago

North Korean Leader Says Past Diplomacy Only Confirmed US Hostility

30 minutes ago

Democrats Strike Deal to Get More Biden Judges Confirmed Before Congress Adjourns

1 hour ago

Newsom Gaslights on Potential Gas Price Hikes in Fresno Visit

President Joe Biden with Mary Barra, the chief executive of General Motors, at the Detroit Auto Show, Sept. 14, 2022. President-elect Donald Trump has promised to erase the Biden administration’s tailpipe rules designed to get carmakers to produce electric vehicles, but most U.S. automakers want to keep them. (Doug Mills/The New York Times)
2 hours ago

Automakers to Trump: Please Require Us to Sell Electric Vehicles

2 hours ago

President Biden Welcomes 2024 NBA Champion Boston Celtics to White House

2 hours ago

Ohtani Makes History With 3rd MVP, Judge Claims 2nd AL Honor

Former Florida Attorney General Pam Bondi, speaks before Republican presidential nominee former President Donald Trump arrives to speak at a campaign rally at First Horizon Coliseum, Saturday, Nov. 2, 2024, in Greensboro, NC. (AP/Alex Brandon)
2 hours ago

Trump Chooses Pam Bondi for Attorney General Pick After Gaetz Withdraws

3 hours ago

Average Rate on a 30-Year Mortgage in the US Rises to Highest Level Since July

Help continue the work that gets you the news that matters most.

Search

Send this to a friend